Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Software Foundation — Vulnerabilities & Security Advisories 2370

Browse all 2370 CVE security advisories affecting Apache Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Apache Software Foundation develops and maintains open-source software, primarily known for the widely deployed Apache HTTP Server and foundational Java frameworks. Its extensive portfolio exposes a significant attack surface, evidenced by the 1717 recorded CVEs. Historically, vulnerabilities frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from complex configuration errors or input validation failures in legacy components. While the foundation enforces rigorous security review processes, the sheer volume of projects increases the likelihood of undiscovered flaws. Notable incidents include critical flaws in Log4j, which allowed remote code execution via crafted log messages, highlighting risks in dependency management. The organization relies on community-driven patching, requiring administrators to promptly apply updates to mitigate exploitation. This model ensures transparency but demands active vigilance from users to maintain system integrity against evolving threat vectors.

CVE ID Title CVSS Severity Published
CVE-2023-51656 Apache IoTDB: Unsafe deserialize map in Sync Tool — Apache IoTDB CWE-502 9.8AI Critical AI 2023-12-21
CVE-2023-48291 Apache Airflow: Improper access control to DAG resources — Apache Airflow CWE-668 4.3AI Medium AI 2023-12-21
CVE-2023-50783 Apache Airflow: Improper access control vulnerability on the "varimport" endpoint — Apache Airflow CWE-284 6.5AI Medium AI 2023-12-21
CVE-2023-47265 Apache Airflow: DAG Params alllow to embed unchecked Javascript — Apache Airflow CWE-79 5.4AI Medium AI 2023-12-21
CVE-2023-49920 Apache Airflow: Missing CSRF protection on DAG/trigger — Apache Airflow CWE-352 8.3AI High AI 2023-12-21
CVE-2023-37544 Apache Pulsar WebSocket Proxy: Improper Authentication for WebSocket Proxy Endpoint Allows DoS — Apache Pulsar WebSocket Proxy CWE-287 7.5 High 2023-12-20
CVE-2023-43826 Apache Guacamole: Integer overflow in handling of VNC image buffers — Apache Guacamole CWE-190 - - 2023-12-19
CVE-2023-49734 Apache Superset: Privilege Escalation Vulnerability — Apache Superset CWE-863 7.7 High 2023-12-19
CVE-2023-49736 Apache Superset: SQL Injection on where_in JINJA macro — Apache Superset CWE-89 6.5 Medium 2023-12-19
CVE-2023-46104 Apache Superset: Allows for uncontrolled resource consumption via a ZIP bomb — Apache Superset CWE-400 6.5 Medium 2023-12-19
CVE-2023-41314 Apache Doris: Missing API authentication allowed DoS — Apache Doris CWE-863 9.1AI Critical AI 2023-12-18
CVE-2023-30867 Apache StreamPark (incubating): Authenticated system users could trigger SQL injection vulnerability — Apache StreamPark (incubating) CWE-89 6.5 - 2023-12-15
CVE-2023-49898 Apache StreamPark (incubating): Authenticated system users could trigger remote command execution — Apache StreamPark (incubating) CWE-77 8.8 - 2023-12-15
CVE-2023-46279 Apache Dubbo: Bypass deny serialize list check in Apache Dubbo — Apache Dubbo CWE-502 9.8 - 2023-12-15
CVE-2023-29234 Bypass serialize checks in Apache Dubbo — Apache Dubbo CWE-502 9.8 - 2023-12-15
CVE-2023-46750 Apache Shiro: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Shiro. — Apache Shiro CWE-601 6.1AI Medium AI 2023-12-14
CVE-2023-45725 Apache CouchDB, IBM Cloudant: Privilege Escalation Using _design Documents — Apache CouchDB CWE-200 7.5AI High AI 2023-12-13
CVE-2023-50164 Apache Struts: File upload component had a directory traversal vulnerability — Apache Struts CWE-552 9.8 - 2023-12-07
CVE-2023-41835 Apache Struts: excessive disk usage — Apache Struts CWE-459 8.2 - 2023-12-05
CVE-2023-49070 Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present — Apache OFBiz CWE-94 9.8 - 2023-12-05
CVE-2023-49735 Apache Tiles: Unvalidated input may lead to path traversal and XXE — Apache Tiles CWE-22 10.0 - 2023-11-30
CVE-2023-49733 Apache Cocoon's StreamGenerator is vulnerable to XXE injection — Apache Cocoon CWE-611 7.5 - 2023-11-30
CVE-2023-49620 Apache DolphinScheduler: Authenticated users could delete UDFs in resource center they were not authorized for — Apache DolphinScheduler CWE-862 4.3 - 2023-11-30
CVE-2022-45135 Apache Cocoon: SQL injection in DatabaseCookieAuthenticatorAction — Apache Cocoon CWE-89 9.8 - 2023-11-30
CVE-2023-42504 Apache Superset: Lack of rate limiting allows for possible denial of service — Apache Superset CWE-770 5.8 Medium 2023-11-28
CVE-2023-42505 Apache Superset: Sensitive information disclosure on db connection details — Apache Superset CWE-200 4.3 Medium 2023-11-28
CVE-2023-42502 Apache Superset: Open Redirect Vulnerability — Apache Superset CWE-601 4.8 Medium 2023-11-28
CVE-2023-46589 Apache Tomcat: HTTP request smuggling via malformed trailer headers — Apache Tomcat CWE-444 7.5 - 2023-11-28
CVE-2022-41678 Apache ActiveMQ: Insufficient API restrictions on Jolokia allow authenticated users to perform RCE — Apache ActiveMQ CWE-287 8.8 - 2023-11-28
CVE-2023-49145 Apache NiFi: Improper Neutralization of Input in Advanced User Interface for Jolt — Apache NiFi CWE-79 7.9 High 2023-11-27

This page lists every published CVE security advisory associated with Apache Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.